Overview
- Researchers at A Security say they used publicly available AI models to find and prototype a working exploit against Zoom’s annotation protocol in under a day with fewer than 20 prompts.
- On Tuesday, August 11, 2026, A Security published a technical write-up and Zoom published fixes and CVE assignments, including CVE-2026-53413, 53414 and 53415 for memory-corruption, buffer over-read and use-after-free bugs.
- The flaws sat in Zoom’s annotator and its proprietary annotation protocol, which opens direct channels between a screen sharer and viewers and let specially crafted messages corrupt client memory for remote code execution.
- Zoom says it rolled out client and server-side patches across Workplace, Rooms, Meeting SDK and VDI builds and that many client fixes were shipped in June and July; there are no confirmed in-the-wild exploit reports.
- The episode raises enterprise risk because zero-click RCE can be silent and cross-platform, and it has prompted debate over AI’s role in lowering exploit barriers plus disputes about CVSS scoring and crediting of findings.